CyberFundamentals (CyFun®) Framework Training

Learn how CyFun® translates the NIS2 Directive into controls, maturity, evidence collection, and conformity assessment | A practical add-on to the PECB NIS2 Directive Lead Implementer and Foundation training courses.

Overview

NIS2 created the pressure; CyFun® creates the path.

CyberFundamentals (CyFun®) Framework Training – The practical implementation of NIS2 in Belgium

Learn how CyFun® translates the NIS2 Directive into controls, maturity, evidence collection, and conformity assessment. A practical add-on to the PECB NIS2 Directive Lead Implementer and Foundation training courses.

This one-day training course is designed for professionals who already understand the NIS2 Directive and now want to learn how its requirements are translated into a practical implementation and evidence-based compliance approach.

The training focuses on the CyberFundamentals Framework (CyFun®), the European framework that helps organizations structure cybersecurity measures, assess maturity, and demonstrate compliance in a practical and measurable way.

This course perfectly complements the PECB NIS2 Directive Lead Implementer and Foundation programs. While NIS2 explains the regulatory requirements and governance framework, CyFun® demonstrates how to operationalize those requirements through controls, assurance levels, self-assessments, maturity scoring, and preparation for verification or certification.

The course is highly practical. Rather than repeating the fundamentals of NIS2, it provides a focused translation of NIS2 into the CyFun® framework. Participants will learn about the different assurance levels, the available tools, how maturity scoring works, what evidence is required, how CyFun® fits within Belgium’s NIS2 implementation, and its role within the broader European cybersecurity landscape.

What is included in the CyberFundamentals (CyFun®) Framework training?

A clear positioning of CyFun® as a practical bridge between NIS2 obligations and actionable cybersecurity measures.

An overview of the origins of CyFun®, the role of the Belgian Centre for Cybersecurity (CCB), and the Belgian NIS2 context.

An in-depth walkthrough of the CyFun® structure: functions, categories, subcategories, controls, requirements, and guidance.

A practical explanation of the Basic, Important, and Essential assurance levels, including how organizations determine the appropriate level.

A walkthrough of the CyFun® tools: selection tool, self-assessment, maturity scores, mappings, key measures, and supporting templates.

An explanation of self-assessment, verification, certification, Conformity Assessment Bodies, and the link with ISO/IEC 27001 as an alternative or parallel pathway.

A European module on NIS2 transposition and the positioning of CyFun® outside Belgium, with a focus on countries where CyFun® is used or being monitored.

An implementation workshop in which participants translate scope and risk into controls, evidence, priorities, and a roadmap.

Practical focus

This training course builds on existing knowledge of NIS2 and focuses on the practical application of the CyberFundamentals Framework (CyFun®).

The fundamental principles of the NIS2 Directive are therefore not covered again in detail.

Learning Objectives

By the end of this training, participants will be able to:

  • understand the structure and organisation of the CyberFundamentals Framework (CyFun®);
  • determine the most appropriate assurance level: Basic, Important, or Essential;
  • translate CyFun® controls into concrete technical and organisational security measures;
  • conduct a CyFun® self-assessment and interpret the results;
  • prepare the required documentation and evidence for conformity assessments;
  • assess maturity levels and determine priorities;
  • develop a practical implementation roadmap.

Program

During this one-day training course, you will learn how the CyberFundamentals Framework (CyFun®) translates NIS2 obligations into concrete cybersecurity measures, maturity assessment, evidence requirements, and demonstrable conformity.

The training course covers, among other topics:

  • the positioning of CyFun® within the Belgian implementation of the NIS2 Directive;
  • the structure of the framework, including functions, categories, subcategories, controls, requirements, and guidance;
  • the different assurance levels — Basic, Important, and Essential — and how to select the appropriate level;
  • the use of CyFun® tools for self-assessments, maturity scoring, mappings, and key measures;
  • documentation and evidence requirements to demonstrate the implementation of controls;
  • the difference between self-assessment, external verification, and certification;
  • the role of Conformity Assessment Bodies (CABs) and the relationship between CyFun® and ISO/IEC 27001;
  • the application of CyFun® within the broader European NIS2 context;
  • a practical workshop in which participants translate scope, risks, controls, and priorities into a concrete implementation roadmap.

This training course is intended for

This training course is designed for professionals involved in the implementation, assessment, or monitoring of the CyberFundamentals Framework (CyFun®) within the context of NIS2, including:

  • NIS2 Lead Implementers, project managers, and programme managers within essential and important entities;
  • CISOs, Information Security Managers, IT Security Managers, and cybersecurity professionals;
  • Risk, compliance, and governance professionals, as well as Data Protection Officers (DPOs), involved in the implementation and monitoring of NIS2 measures;
  • Consultants and auditors who support organisations with CyFun® implementations, gap analyses, maturity assessments, and conformity assessments;
  • Professionals who have attended a PECB NIS 2 Foundation or Lead Implementer training course and wish to deepen their knowledge through the practical application of CyFun®.

Basic knowledge of NIS2 is recommended.

Exam & Certificate

Upon completion of the training, participants will receive a certificate of attendance confirming that they attended the training on the practical application of the CyberFundamentals Framework (CyFun®) and on translating NIS2 obligations into controls, maturity levels, evidence requirements, and conformity assessment.

An optional PECB package with self-study materials for PECB NIS 2 Directive Foundation, PECB NIST Cybersecurity Framework Foundation, PECB ISO/IEC 27001 Foundation, or PECB Cybersecurity Foundation, including access to the corresponding PECB exam and one free exam retake.

 

 

The CyFun® Framework is a framework owned by the Centre for Cybersecurity Belgium (CCB), operating under the authority of the Prime Minister of Belgium.

The abbreviation “CyFun®” stands for “Cyberfundamentals Framework” and is a registered trademark owned by the CCB.

The CyFun® Framework and CyFun® Conformity Assessment Scheme (CAS) are available on www.cyfun.eu, which is their only authentic source.

The services offered by NIS Institute may contribute to third party assessments, but they do not replace nor fulfil any accredited third-party assessment as described by the CyFun® Framework. Therefore, NIS Institute can never claim that its services fully meet the requirements of the CyFun® Framework and the services cannot be considered for use in conformity assessments resulting in obtaining a presumption of conformity with the NIS2 Directive and its Belgian transposition.

If there is any discrepancy between the products and services offered by NIS Institute and the documents on the website, only the latest version of the documents on the website is deemed authentic.

Make your choice

The CyberFundamentals (CyFun®) Framework course is organised in a Virtual Classroom during one full day.

940 € excl. VAT

Training Calendar